QID 379027

QID 379027: IBM WebSphere Application Server Liberty Information Disclosure Vulnerability (7076305)

IBM WebSphere Application Server Liberty could provide weaker than expected security due to improper resource expiration handling

Affected Versions:
WebSphere Application Server Liberty Version 17.0.0.3 - 23.0.0.11
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.

Successful exploit could allow a remote authenticated attacker to obtain sensitive information

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    For more information kindly refer 7076305
    Vendor References

    CVEs related to QID 379027

    Software Advisories
    Advisory ID Software Component Link
    7076305 URL Logo www.ibm.com/support/pages/node/7076305